CVE-2023-47256

MEDIUM

ConnectWise ScreenConnect < 23.8.5 - Implicit Trust of Proxy Settings

Title source: llm
STIX 2.1

Description

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

Scores

CVSS v3 5.5
EPSS 0.0044
EPSS Percentile 35.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
connectwise/automate
connectwise/screenconnect < 23.8.5
Published Feb 01, 2024
Tracked Since Feb 18, 2026